CVE-2016-0930
Severity CVSS v4.0:
Pending analysis
Type:
CWE-362
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
Publication date:
18/09/2016
Last modified:
12/04/2025
Description
Pivotal Cloud Foundry (PCF) Ops Manager before 1.6.19 and 1.7.x before 1.7.10, when vCloud or vSphere is used, has a default password for compilation VMs, which allows remote attackers to obtain SSH access by connecting within an installation-time period during which these VMs exist.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:pivotal:operations_manager:*:*:*:*:*:*:*:* | 1.6.18 (including) | |
| cpe:2.3:a:pivotal:operations_manager:1.7.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:pivotal:operations_manager:1.7.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:pivotal:operations_manager:1.7.2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:pivotal:operations_manager:1.7.3:*:*:*:*:*:*:* | ||
| cpe:2.3:a:pivotal:operations_manager:1.7.4:*:*:*:*:*:*:* | ||
| cpe:2.3:a:pivotal:operations_manager:1.7.5:*:*:*:*:*:*:* | ||
| cpe:2.3:a:pivotal:operations_manager:1.7.6:*:*:*:*:*:*:* | ||
| cpe:2.3:a:pivotal:operations_manager:1.7.7:*:*:*:*:*:*:* | ||
| cpe:2.3:a:pivotal:operations_manager:1.7.8:*:*:*:*:*:*:* | ||
| cpe:2.3:a:pivotal:operations_manager:1.7.9:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



